tag:blogger.com,1999:blog-33637086867060703832024-03-29T07:25:09.999+00:00Tony's BlogTonyhttp://www.blogger.com/profile/00446535470734199043noreply@blogger.comBlogger705125tag:blogger.com,1999:blog-3363708686706070383.post-88219089638553658842024-02-04T19:53:00.004+00:002024-02-04T19:53:53.139+00:00Sunshine Sanctuary for Sick Dragons appeal<iframe frameborder="0" height="270" src="https://youtube.com/embed/PWWtopEZsTo?si=GAMxC_fbcr2BaAbI" width="480"></iframe><div><div>Goodboy was one of the lucky ones! He was found by the Sunshine Sanctuary for Sick Dragons in Morphic Street, Ankh Morpork. Here he will be well fed, and well cared for.</div><div>Terry Prachett's® Guards! Guards A Discworld play® adapted by Stephen Briggs</div><div>Wednesday 14th to Saturday 17th February 2024</div><div><a href="http://ticketsource.co.uk/midlandplayers">http://ticketsource.co.uk/midlandplayers</a></div></div><div class="blogger-post-footer"><a rel="license" href="http://creativecommons.org/licenses/by-sa/2.0/uk/">
<img alt="Creative Commons License" style="border-width:0" src="http://www.pint.org.uk/stuff/cc.png" />
</a></div>Tonyhttp://www.blogger.com/profile/00446535470734199043noreply@blogger.com1tag:blogger.com,1999:blog-3363708686706070383.post-90351311649004699592024-01-02T20:04:00.007+00:002024-01-02T20:04:56.381+00:00The weather forecast<p></p><div class="separator" style="clear: both; text-align: center;"><iframe allowfullscreen="" class="BLOG_video_class" height="266" src="https://www.youtube.com/embed/laZarp2WKAc" width="320" youtube-src-id="laZarp2WKAc"></iframe></div><br /> Terry Prachett's® Guards! Guards! a Discworld® play adapted by Stephen Briggs <p></p><p>Sheffield University Drama Studio Shearwood Rd, Sheffield S10 2TD</p><p>The show runs from Wednesday 14th to Saturday 17th February 2024 starting at 7:30pm. Doors open at 7:00pm and there will be some pre-show action from 7:15pm so don't be late!</p><p><a href="https://www.ticketsource.co.uk/midlandplayers">https://www.ticketsource.co.uk/midlandplayers</a></p><div class="blogger-post-footer"><a rel="license" href="http://creativecommons.org/licenses/by-sa/2.0/uk/">
<img alt="Creative Commons License" style="border-width:0" src="http://www.pint.org.uk/stuff/cc.png" />
</a></div>Tonyhttp://www.blogger.com/profile/00446535470734199043noreply@blogger.com2tag:blogger.com,1999:blog-3363708686706070383.post-24362863403657437072023-12-31T22:58:00.000+00:002023-12-31T22:58:24.875+00:00Herbert Gaskin reports in #terrypratchett<iframe style="background-image:url(https://i.ytimg.com/vi/u1dWTJ7JpUk/hqdefault.jpg)" width="480" height="270" src="https://youtube.com/embed/u1dWTJ7JpUk?si=pzgxoG1r-rdsHWT4" frameborder="0"></iframe><div class="blogger-post-footer"><a rel="license" href="http://creativecommons.org/licenses/by-sa/2.0/uk/">
<img alt="Creative Commons License" style="border-width:0" src="http://www.pint.org.uk/stuff/cc.png" />
</a></div>Tonyhttp://www.blogger.com/profile/00446535470734199043noreply@blogger.com1tag:blogger.com,1999:blog-3363708686706070383.post-5178466705591890292023-12-24T20:01:00.003+00:002023-12-24T20:01:46.378+00:00Happy Hogswatch<p></p><div class="separator" style="clear: both; text-align: center;"><iframe allowfullscreen="" class="BLOG_video_class" height="313" src="https://www.youtube.com/embed/rNJO3ENRc_E" width="377" youtube-src-id="rNJO3ENRc_E"></iframe></div><br /> Terry Pratchett's GUARDS! GUARDS!<p></p><p>A Discworld™️ play. Adapted by Stephen Briggs. 14th-17th February. Presented by Midland Players at the Sheffield University Drama Studio. </p><p><a href="https://www.ticketsource.co.uk/midlandplayers" rel="nofollow" target="_blank">Buy tickets now </a><br /></p><div class="blogger-post-footer"><a rel="license" href="http://creativecommons.org/licenses/by-sa/2.0/uk/">
<img alt="Creative Commons License" style="border-width:0" src="http://www.pint.org.uk/stuff/cc.png" />
</a></div>Tonyhttp://www.blogger.com/profile/00446535470734199043noreply@blogger.com0tag:blogger.com,1999:blog-3363708686706070383.post-55474855807189077152023-12-16T22:51:00.003+00:002023-12-16T22:51:19.639+00:00A glimpse into the rehearsal room Part 2<p></p><div class="separator" style="clear: both; text-align: center;"><iframe allowfullscreen="" class="BLOG_video_class" height="312" src="https://www.youtube.com/embed/rxtBjX8IPJU" width="376" youtube-src-id="rxtBjX8IPJU"></iframe></div><br /> <p></p><div class="blogger-post-footer"><a rel="license" href="http://creativecommons.org/licenses/by-sa/2.0/uk/">
<img alt="Creative Commons License" style="border-width:0" src="http://www.pint.org.uk/stuff/cc.png" />
</a></div>Tonyhttp://www.blogger.com/profile/00446535470734199043noreply@blogger.com0tag:blogger.com,1999:blog-3363708686706070383.post-90729558521548816112023-12-16T21:11:00.006+00:002023-12-16T21:11:57.084+00:00Take a peak at what is happening at rehearsals part 1.<p></p><div class="separator" style="clear: both; text-align: center;"><iframe allowfullscreen="" class="BLOG_video_class" height="412" src="https://www.youtube.com/embed/mhmmgClXkq8" width="495" youtube-src-id="mhmmgClXkq8"></iframe></div><br /> <p></p><div class="blogger-post-footer"><a rel="license" href="http://creativecommons.org/licenses/by-sa/2.0/uk/">
<img alt="Creative Commons License" style="border-width:0" src="http://www.pint.org.uk/stuff/cc.png" />
</a></div>Tonyhttp://www.blogger.com/profile/00446535470734199043noreply@blogger.com0tag:blogger.com,1999:blog-3363708686706070383.post-14984314239921459232023-11-07T21:31:00.001+00:002023-11-07T21:31:11.950+00:00Terry Pratchett's GUARDS! GUARDS! A Discworld Play #shorts<iframe frameborder="0" height="270" src="https://youtube.com/embed/VsaGktUL61U?si=deFi3FoRVRuItbv2" width="480"></iframe><div>Adapted by Stephen Briggs, presented by Midland Players at the Sheffield University Drama Studio.</div><div class="blogger-post-footer"><a rel="license" href="http://creativecommons.org/licenses/by-sa/2.0/uk/">
<img alt="Creative Commons License" style="border-width:0" src="http://www.pint.org.uk/stuff/cc.png" />
</a></div>Tonyhttp://www.blogger.com/profile/00446535470734199043noreply@blogger.com1tag:blogger.com,1999:blog-3363708686706070383.post-8098807153895845512023-10-07T23:58:00.007+01:002023-10-07T23:58:50.685+01:00Auditions #short<iframe frameborder="0" height="270" src="https://youtube.com/embed/jTSYrdugQKc?si=mjbzmMxFClZRi9XN" width="480"></iframe><div><div>Open auditions for Guards! Guards!</div><div>Please come on Tuesday 10th October at 7.30 pm or Saturday 14th October at 4pm to the Red Deer on Pitt Street </div><div>(you only need to come to one)</div><div>There are loads of roles available, from a couple of lines to genuine Discworld legends.</div><div>The process is several rounds of being thrown into groups or being asked to monologue with pieces handed out on the night, you get time to prepare your bit and then present it back to the whole room. If sight reading is an issue for any reason please drop me a message and accommodations can be made.</div><div>Unfortunately the audition venue and a significant proportion of the rehearsal rooms are up stairs.</div></div><div class="blogger-post-footer"><a rel="license" href="http://creativecommons.org/licenses/by-sa/2.0/uk/">
<img alt="Creative Commons License" style="border-width:0" src="http://www.pint.org.uk/stuff/cc.png" />
</a></div>Tonyhttp://www.blogger.com/profile/00446535470734199043noreply@blogger.com0tag:blogger.com,1999:blog-3363708686706070383.post-44211580496897701702023-10-05T20:17:00.000+01:002023-10-07T23:59:05.105+01:00Guards! Guards! by Terry Pratchett #shorts<iframe frameborder="0" height="270" src="https://youtube.com/embed/6uZz8xEShHs?si=im-OVa_AX4Evzjg5" width="480"></iframe><div><div>Announcement. The Elucidated Brethren of the Ebon Night, sorry Midland Players and I, are staging Guards! Guards! by Terry Pratchett adapted by Stephen Briggs </div><div>Lots of parts of all sizes[1] audition information and a call for backstage participation coming very soon. Please drop me a line if you want more information.</div><div><br /></div><div>[1] stop sniggering at the back [2]</div><div>[2] actually please don't</div></div><div class="blogger-post-footer"><a rel="license" href="http://creativecommons.org/licenses/by-sa/2.0/uk/">
<img alt="Creative Commons License" style="border-width:0" src="http://www.pint.org.uk/stuff/cc.png" />
</a></div>Tonyhttp://www.blogger.com/profile/00446535470734199043noreply@blogger.com3tag:blogger.com,1999:blog-3363708686706070383.post-77606385713552916232023-06-14T11:49:00.000+01:002023-06-14T11:49:54.306+01:00 Projects I am currently working on (and where they're at):<dl>
<dt>A Wear OS watch app which keeps track of train journeys, showing a "complication" which shows how long it has left and the platform number of your connection (if applicable).</dt>
<dd>I <i>think</i> I have most of what I need for this, the data feeds, how to do the complication in Watch Studio, how to get the data from one to the other. I just have a few bits where I can't decide on frequencies and setting up the trigger for updates.</dd>
<dt>A Wear OS watch app that displays <a href="https://picturesofpeoplescanningqrcodes.tumblr.com/" target="_blank">QR code tickets</a>. Starting with cinema (not trains atm because I'm not sure the rules)</dt>
<dd>An AWS lambda in JS to turn the emails into just key data and the QR code seems fairly easy. I am trying to see if I can get my head around kotlin and the associated android APIs, I'm not currently winning but I'm not ready to give up. I might go back to my original plan of this being <a href="https://shop.pimoroni.com/products/badger-2040-w?variant=40514062188627" target="_blank">an e-ink thing</a>, but the watch has some advantages.</dd>
<dt>Moving my home automation over to <a href="https://www.home-assistant.io/" target="_blank">home assistant</a></dt>
<dd>It gives me a good framework so I don't have to write the meat of an automation system. And it has stuff built in, or community contributed, that talks to a whole bunch the stuff I already have, I just need to rewrite the stuff that talks to my custom lights built on the <a href="https://shop.pimoroni.com/products/plasma-stick-2040-w?variant=40359072301139" target="_blank">Plasma Stick 2040 W</a></dd>
<dt>CCTV</dt>
<dd>Something something off-site backups, something. This has involved a lot of yak shaving, (often held up by systemd-resolved.service being pants). I think the expansion of features on the <a href="https://tailscale.com/">free Tailscale plan</a>, and the OpenWrt port seeming to be stable may deliver some moderatly pre-shaved yaks.</dd>
</dl>
<p>As ever a combination of factors are at play in how they are progressing, not least that I am not really concentrating on any one of them. Other things include remembering to have local copies of stuff before getting on trains, trying to do things in languages/ecosystems I am learning as I go along (the greatest lie kotlin ever told was sprinkling "fun" through the source ;->) and my star-sign being the opposite to completer finisher (with mercury in retrograde). Drop a comment if you have any questions.</p>
<div class="blogger-post-footer"><a rel="license" href="http://creativecommons.org/licenses/by-sa/2.0/uk/">
<img alt="Creative Commons License" style="border-width:0" src="http://www.pint.org.uk/stuff/cc.png" />
</a></div>Tonyhttp://www.blogger.com/profile/00446535470734199043noreply@blogger.com6tag:blogger.com,1999:blog-3363708686706070383.post-58281629278363788112023-06-12T10:43:00.000+01:002023-06-12T10:43:04.845+01:00Good news, research shows you can reduce your exposure to arsenic from eating rice.<div>Firstly: I want to point out that the Food Standards Agency does not recommend cutting rice out of your diet, and there are regulations about how much arsenic there is in our food. </div><div><br /></div><div><br /></div><div style="text-align: center;"><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen="" frameborder="0" height="315" src="https://www.youtube.com/embed/MPUddbjS6BY" title="YouTube video player" width="560"></iframe></div><div>They do however make a specific point about not using rice milk as a substitute for breast milk, infant formula, or cow's milk for children under 5.</div><div><br /></div><div>Go to <a href="https://www.food.gov.uk/safety-hygiene/arsenic-in-rice" target="_blank">https://www.food.gov.uk/safety-hygiene/arsenic-in-rice</a> for more information. Or <a href="https://www.youtube.com/watch?v=Pbu6kz_ZBJY" target="_blank">watch this explanatory video</a>.</div><h2 style="text-align: left;">On to the good news.</h2><div>In <a href="https://www.sciencedirect.com/science/article/pii/S0048969720368728" target="_blank">a paper published in Science of The Total Environment</a> (Volume 755, Part 2), researchers from the University of Sheffield and UCLA compared four different methods of preparing rice before using the absorption method of cooking whether this was in a pan, rice cooker or pressure cooker.</div><div><br /></div><div>The four methods were: not washing the rice, washing the rice, soaking the rice and parboiling the rice before discarding the water.</div><div><br /></div><div>The parboiling method removed 73% of the inorganic arsenic from the white rice.</div><div><br /></div><div>The procedure in the paper is as follows</div><div><ul style="text-align: left;"><li>Into a pan put 4 cups of water for every cup of raw rice, and bring to the boil</li><li>Add the rice and boil for a further 5 minutes</li><li>Drain and discard the water</li><li>Using fresh water, finish cooking the rice using the absorption method.</li></ul></div><div class="separator" style="clear: both; text-align: center;"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgihYKVin0tMuGc-jdAK0ezBybdquBmDjjk_AIpFMVyC3MWUV7c6CT7uoheRANNLKPi2GV26dyeUlp3ukHDfwCp9PtiaDcqqs8L9Z9JsBovH2A-uIkYjhQXYAa2DHkQKQ3tAcZPrIELAnTO29tnfqBc39FgaIJusAozB7xcVuOpUhQf2RrucYn5OGhO8w/s1535/1-s2.0-S0048969720368728-ga1_lrg.jpg" style="margin-left: 1em; margin-right: 1em;"><img alt="A diagrammatic representation of the method described above. There are also three info bubbles outlining advantages 'Highly effective for removing inorganic arsenic from brown (54%) and white rice (73%)' 'Safer for preparing rice for infants and children as the margin of exposure is increased to desired levels' 'Reduced nutrient element losses and home friendly (saving time, water and energy)'" border="0" data-original-height="886" data-original-width="1535" height="231" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgihYKVin0tMuGc-jdAK0ezBybdquBmDjjk_AIpFMVyC3MWUV7c6CT7uoheRANNLKPi2GV26dyeUlp3ukHDfwCp9PtiaDcqqs8L9Z9JsBovH2A-uIkYjhQXYAa2DHkQKQ3tAcZPrIELAnTO29tnfqBc39FgaIJusAozB7xcVuOpUhQf2RrucYn5OGhO8w/w400-h231/1-s2.0-S0048969720368728-ga1_lrg.jpg" title="Parboiling with absorption method (PBA)" width="400" /></a></div><br /><div><br /></div><div>Finally a huge vote of thanks to <a href="https://www.youtube.com/channel/UCBJSV7--bFqPrxIjHPQQd8g" target="_blank">HAUS OF PETTY</a> who posted a video on TikTok about arsenic in white rice, that lead me down the rabbit hole of looking to see if there was anything you could do to deal with it at home. </div><div class="blogger-post-footer"><a rel="license" href="http://creativecommons.org/licenses/by-sa/2.0/uk/">
<img alt="Creative Commons License" style="border-width:0" src="http://www.pint.org.uk/stuff/cc.png" />
</a></div>Tonyhttp://www.blogger.com/profile/00446535470734199043noreply@blogger.com6tag:blogger.com,1999:blog-3363708686706070383.post-68709643579852001462023-04-25T17:59:00.000+01:002023-04-25T17:59:12.802+01:00Silence and consent<p>Terrance Eden has written a blog post entitled “<a href="https://shkspr.mobi/blog/2023/04/silence-isnt-consent/" rel="nofollow">Silence Isn't Consent</a>” it is a tale of someone hammering one of his sites with a bot and the writer of that bot being quite a bit of an arse.</p><p>The post left me with two strong things I wanted to say. The first is easy to express, that the use of the term “enthusiastic consent” and the specific linking to a PSHE post on the subject made me feel quite icky. To quote the post explicitly “<i>I know what they meant and, it some contexts, it's an understandable shortcut.</i>” but having your content scraped should not even as a metaphor be equated to sexual activity without consent. </p><p>The second was that this the issue of what people can and can't do with your content is important, and we have a framework for this, licences. Now Terrance doesn't say which of his sites the tool went after. If it was the blog he wrote the post on, <a href="https://shkspr.mobi/blog/copyright-terence-eden/" rel="nofollow">he actively claims as much control over the copyright as he can</a>, but if it was <a href="https://openbenches.org/">openbenches.org</a> that is published under the <a href="https://creativecommons.org/licenses/by-sa/4.0/" rel="nofollow" target="_blank">Creative Commons Attribution-ShareAlike 4.0 International (CC BY-SA 4.0)</a> license. So it isn't (I don't think) possible to spot breach of that just by the content being scraped. </p><blockquote><p style="text-align: left;">Thousands of tools are released every day. Am I expected to play whack-a-mole and shut down every new one that appears?</p><p style="text-align: right;">Terrance Eden - '<a href="https://shkspr.mobi/blog/2023/04/silence-isnt-consent/" rel="nofollow">Silence Isn't Consent</a>'</p></blockquote>
<p>This 100% shouldn't need whack-a-mole, this activity should be covered by licences, this may need extra work, especially if we want to include rate limits in those agreements. And licencing needs to become as much covered by standard machine readable ways of highlighting as search engine inclusion (something in theory you specify once with headers, or meta-tags, or a text file, and everyone obeys.</p><p>However this is as much a “Nice to have” at this precise point as Terrance's ask to have an “<i>opt in</i>” to bots, and as for consent, even if you don't make icky equivalences about the web and the really real world, there is a ton of evidence that the vast majority of people on the internet don't understand it, even if reams of guidance are issued. just look at how badly most people implement it for cookies.</p><div class="blogger-post-footer"><a rel="license" href="http://creativecommons.org/licenses/by-sa/2.0/uk/">
<img alt="Creative Commons License" style="border-width:0" src="http://www.pint.org.uk/stuff/cc.png" />
</a></div>Tonyhttp://www.blogger.com/profile/00446535470734199043noreply@blogger.com15tag:blogger.com,1999:blog-3363708686706070383.post-47553252005112535672023-01-16T15:24:00.002+00:002023-01-16T15:24:51.703+00:00Voter Authority Certificate (voter ID)<p>Under the cover of beating in-person voter fraud, a problem that simply just does not exist, the Tories have introduced a requirement for ID to vote. This will disenfranchise a lot of poor and marginalised people.</p><p>If you do not have one of the following:</p><p></p><ul style="text-align: left;"><li>UK or EEA Photocard driving licence</li><li>UK, Channel Islands, Isle of Man, a Commonwealth, British Overseas Territory or EEA Passport (valid or expired)</li><li>UK Proof of Age Standards Scheme (PASS) card</li><li>UK biometric residence permit</li><li>UK Defence identity card (MOD Form 90)</li><li>Northern Ireland Electoral Identity Card</li><li>National ID from an EEA country</li><li>Blue Badge</li><li>Government travel pass for older or disabled people Including Freedom pass, or disabled person’s concessionary pass</li><li>Scottish National Entitlement Card</li></ul><div>Then you will need to acquire one or <a href="https://voter-authority-certificate.service.gov.uk/apply" target="_blank">apply for a Voter Authority Certificate</a>. </div><p></p><div>You need:</div><div><ul style="text-align: left;"><li>your registered voting address, </li><li>a recent, digital photo, </li><li>your National Insurance number</li></ul></div><div>Applying takes around 5 minutes, or 20 minutes if you cannot provide a National Insurance number.</div><div>There is <a href="https://voter-authority-certificate.service.gov.uk/voter-authority-certificate-application-form.pdf" target="_blank">a paper form</a>.</div><div>There is a different process for<a href="https://voter-authority-certificate.service.gov.uk/check/exit/anonymous-elector" target="_blank"> anonymous electors</a>.</div><div>The Electoral Commission has <a href="https://www.electoralcommission.org.uk/i-am-a/voter/voter-id" target="_blank">more information about Voted ID</a>. There is also <a href="https://commonslibrary.parliament.uk/research-briefings/cbp-9187/" target="_blank">a briefing from the House of Commons library</a>.</div><div class="blogger-post-footer"><a rel="license" href="http://creativecommons.org/licenses/by-sa/2.0/uk/">
<img alt="Creative Commons License" style="border-width:0" src="http://www.pint.org.uk/stuff/cc.png" />
</a></div>Tonyhttp://www.blogger.com/profile/00446535470734199043noreply@blogger.com8tag:blogger.com,1999:blog-3363708686706070383.post-55877162171316983062021-05-21T16:33:00.000+01:002021-05-21T16:33:56.041+01:00The BBC still have reputational issues due to outsourcing<p>Ten years after I wrote a story about sub-sub-contractors <a href="https://blog.pint.org.uk/2011/03/bbc-is-risking-its-reputation.html" target="_blank">causing reputational problems for the BBC</a> because the public will look at the big household name on the sign, not the logo on the badge there is another classic example.</p>
<p>After <a href="https://www.bbc.co.uk/news/uk-wales-57201074">a night of riots</a> in Swansea, someone with access to post to the HIGNFY twitter feed from the VIth form common room, tweeted a joke so old even the Goon Show probably decided they couldn't get away with it even if they lampshaded it. I won't repeat it here, but if you have welsh heritage you can probably guess with a fair degree of accuracy if I say it isn't about sheep or rain.</p>
<blockquote class="twitter-tweet"><p dir="ltr" lang="en">It's not by the BBC. It's not even by anyone working on HIGNFY. Hat Trick farms out the content of much of the HIGNFY Twitter feed to outside 'content providers'. I'm not a fan of much of it, and have said as much to producers.</p>— Ged Parsons (@GedParsons) <a href="https://twitter.com/GedParsons/status/1395757453812375554?ref_src=twsrc%5Etfw">May 21, 2021</a></blockquote> <script async="" charset="utf-8" src="https://platform.twitter.com/widgets.js"></script>
<p>The distance this person is from “Sitting in an office at Television Centre” is well known to those in the know, but to the vast majority of people on twitter “the sign above the door” says BBC and i don't really think they need any more reputational damage right now for the hypocrites in the rest of the media to latch on to.</p><div class="blogger-post-footer"><a rel="license" href="http://creativecommons.org/licenses/by-sa/2.0/uk/">
<img alt="Creative Commons License" style="border-width:0" src="http://www.pint.org.uk/stuff/cc.png" />
</a></div>Tonyhttp://www.blogger.com/profile/00446535470734199043noreply@blogger.com33tag:blogger.com,1999:blog-3363708686706070383.post-9449282567327895382021-02-17T13:24:00.000+00:002021-02-17T14:22:49.432+00:00Proofreading help request<p>This is something I have written for a project I am currently writing. Any corrections/suggestions gratefully recieved.</p>
<h2>Advice on setting and managing passwords</h2>
<p>This is a selection of advice on setting and managing password when signing up to a site on the internet. The idea is that anyone who doesn't have a lot of experience with the world wide web isn't just thrown in at the deep end.</p>
<p>If you just want the short version: use a password manager and take advantage of not having to remember all your passwords to set a different complex password on every site. Also take especially good care of your email account password.</p>
<h3 id="managers">Password Managers</h3>
<p>If you take nothing else away from reading this then I hope you start using a password manager. You may have heard that they are a risk. Yes they are, like all software it is incredibly difficult to ensure they are entirely free of errors however I subscribe to the view that <a href="https://www.troyhunt.com/password-managers-dont-have-to-be-perfect-they-just-have-to-be-better-than-not-having-one/">Password managers don't have to be perfect, they just have to be better than not having one</a><small><sup>[<a href="footnote1">1</a>]</sup></small>. There are three main options for you:
</p><h4>3rd party password managers</h4>
<p>When people talk about <a href="https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online/password-managers">password managers</a>, they invariably mean 3rd party software that you use to store your passwords. The full run down on how to pick on and why that one will be the right one for you would take a very long article itself but there are three main questions to ask yourself.</p>
<dl>
<dt>Are you signing into lots of websites and apps across several computers/devices?</dt>
<dd>If this is the case you'll need to look at the options for sharing the passwords across devices. This may come as standard or as a paid upgrade. Some managers use your existing storage (Dropbox, Google Drive, One Drive etc.) to do this, in that case you need to make very sure that you don't put anything that can be used to guess your master password in that storage.</dd>
<dt>Are you good at remembering passwords?</dt>
<dd>It might seem silly to ask this when talking about finding a service designed to remember passwords for you, but you still have to remember one very important one, that gets you into your password manager. As a general principle those password managers that are a web based service themselves are more likely to have account recovery tools, but do make sure to double check.</dd>
<dt>Will you want to share passwords with other people?</dt>
<dd>This is easy in some managers although you may need to pay extra for it, while in others you can't do it without sharing the whole set of passwords and giving the other person your master password.</dd>
</dl>
<p>A few that you might want to look into are: <a href="https://www.lastpass.com/">Lastpass</a>, <a href="https://1password.com/">1Password</a>, <a href="https://bitwarden.com/">Bitwarden</a>, <a href="https://www.enpass.io/">Enpass</a>, <a href="https://keepass.info/">keepass</a>.
</p><h4>Browser built ins</h4>
<p>If you use the same web browser whenever you use the internet then you can just use that to store passwords (it is probably nagging you to do this already). This can even work across multiple computers/devices if you are signed into the browser and it is syncing your data. All the major browsers offer this, although it can run into issues if you don't use the same brand of devices as your main computer. These built in password managers offer encrypted storage and complex password suggestions.
</p><h4>A diary</h4>
<p>If you have ever worked in an office you have probably been told that writing passwords down is a terrible thing to do. And they will have been right, when thinking about the risks that exist in an office, which are mainly other employees and those attempting to get private company information to sell to competitors<small><sup>[<a href="footnote2">2</a>]</sup></small>. In your home life the risks are very different, and for most people that is online ne'er-do-wells trying to get your personal information and bank card numbers, in this situation passwords, written in a book, locked in a drawer is a sensible choice.</p>
<h3 id="Password">Creating a Password</h3>
<h4>Completely random strings</h4>
<p>Now you have been convinced to use a password manager, you can just use the “generate password” feature and away you go (although you may need to fiddle with the settings to deal with different rules sites have about what needs to be in a password).</p>
<p>If you are not using a password manager, or yours doesn't come with a random password generator, try one of these ideas:</p>
<h4>Three random words</h4>
<p>Otherwise known as <a href="https://xkcd.com/936/">Correct Horse Battery Staple</a> after a cartoon, <a href="https://www.ncsc.gov.uk/blog-post/three-random-words-or-thinkrandom-0">Three random words or #thinkrandom</a> is a way to generate passwords that are both strong and memorable. This is the method the “Generate Password” button uses. I would actually advise against using this function if you have to remember the password as it will always be more memorable if you come up with the words yourself. However if you need inspiration or are using a password manager to remember the password, go right ahead. If you are on a site that wants numbers or punctuation characters, you can add some at the end or swap out letters i or l becomes 1, a becomes 4 and so on, or make up your own.</p>
<h4>I see a little silhouetto of a man, Scaramouche, Scaramouche, Will you do the Fandango?</h4>
<p>Another way to create memorable passwords that are difficult for someone else to guess is to take a phrase, saying, quote, song lyric or similar and use the initials. So “I see a little silhouetto of a man, Scaramouche, Scaramouche, Will you do the Fandango?” becomes “IsalsoamSSWydtF?” if the password rules require numbers or punctuation characters you can substitute them in, or just use a phrase that has them in to start with “There are 106 miles to Chicago, we have a full tank of gas, half a pack of cigarettes, it's dark and we're wearing sunglasses!”</p>
<h3 id="Other">Other considerations</h3>
<h4>But this page contradicts what I have been told by someone</h4>
<p>For a start, different risks need different levels of protection, this advice is good enough for most websites but might not fly for systems containing large amounts of sensitive, personal, or financial information. It also benefits from not having to line up with lots of external rules and regulations. If you want a good all round read on passwords try “<a href="https://www.ncsc.gov.uk/collection/passwords/updating-your-approach">Password policy: updating your approach</a>”.</p>
<h4>You've got mail</h4>
<p>Even if they have other steps involved like security questions (don't forget you don't have to tell the truth for these, three random words works especially well for them if you might need to use them over the phone) most self-service password reset systems rely on the idea that your email account is secure and you are the only person who has access to it (or at least you trust everyone who does implicitly) so <a href="https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online/use-a-strong-and-separate-password-for-email">use a strong and unique password for your email</a> (and if you can think about turning on <a href="https://www.ncsc.gov.uk/guidance/setting-two-factor-authentication-2fa">2 factor authentication</a>).</p>
<h4>What if my password is stolen</h4>
<p>One of the reasons to not remember passwords yourself is that best practice is to use a different one for every different login. Why? Because when someone gets hold of a stolen database of passwords, they will often try those passwords out on other sites, if people have used the same details there then they can get in. This is especially a problem these days where most sites don't ask you to set a separate user-name, but just use email addresses. There is a service called “<a href="https://haveibeenpwned.com/Passwords">Pwned Passwords</a>” that will allow you to check if a password has appeared in one of the many databases that has been stolen and posted on the internet<small><sup>[<a href="footnote3">3</a>]</sup></small>. This is what we use to check your password before we will accept it. This functionality or similar is now being built into several password managers and similar products. If you are wondering about the name, then just understand that like any group <a href="https://en.wikipedia.org/wiki/Leet">nerds have their own jargon</a>.</p>
<h4 id="DangerWillRobinson">How worried should I be if my password is in the pwnedpasswords.com list</h4>
<p>It depends. If your password is Fido2018 then it might not be your password but someone else's that is in the list and they don't have the association with your email address. After all how many hundreds of people will have got a dog in 2018 and called it Fido. You should probably still change it just in case it is your actual password (and in this case it is a very poor password). On the other hand if it is unlikely that anyone else has the same password and you have used it on multiple sites then it is probably best if the first thing you do after getting your new password manager is spend an evening changing all your passwords.</p>
<hr>
<div id="footnotes">
<p id="footnote1">[1] There are of course people working in high security jobs for whom this doesn't hold true, but I don't expect them to be reading this advice.</p>
<p id="footnote2">[2] Your company risk profile may vary, but whatever it is, it is unlikely to be the cat trying to order Dreamies in bulk which is a multi-million-pound issue in home information security.</p>
<p id="footnote3">[3] There is a companion service called “<a href="https://haveibeenpwned.com/">Have I Been Pwned</a>” that will take your email address and let you know if they appear in any stolen databases that they know of.</p>
<p id="footnote4">[4] <a href="https://www.troyhunt.com/ive-just-launched-pwned-passwords-version-2/#cloudflareprivacyandkanonymity">This section</a> of a very long blog post about the system explains how we can check a password is or isn't in the data set without either revealing the password to the service or downloading 650 million passwords to search ourselves.</p>
</div> <p></p><p></p><p></p><div class="blogger-post-footer"><a rel="license" href="http://creativecommons.org/licenses/by-sa/2.0/uk/">
<img alt="Creative Commons License" style="border-width:0" src="http://www.pint.org.uk/stuff/cc.png" />
</a></div>Tonyhttp://www.blogger.com/profile/00446535470734199043noreply@blogger.com44tag:blogger.com,1999:blog-3363708686706070383.post-39666435610759549772021-01-19T18:49:00.000+00:002021-01-19T18:49:40.681+00:00Where is the next big (little) think in home automation?<div class="separator" style="float: right; margin-bottom: 1em; margin-left: 1em; text-align: center;"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhqOh8k6Eyi72HMqNqS3XnM2NrEKkX_cEE0eIUDlAbav0dx8Qv21gI_llCjKj4v2uTazQNSzOczXjwi3BbeLUHJMOXvSBYx2PoP8tIG2MGR46pFX3z00S9P0dXniA0-pLvfaPfsIRGECG1k/" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"><img alt="Child's drawing of a yellow house" data-original-height="1150" data-original-width="1599" height="230" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhqOh8k6Eyi72HMqNqS3XnM2NrEKkX_cEE0eIUDlAbav0dx8Qv21gI_llCjKj4v2uTazQNSzOczXjwi3BbeLUHJMOXvSBYx2PoP8tIG2MGR46pFX3z00S9P0dXniA0-pLvfaPfsIRGECG1k/" title="'yellow house child drawing' By Øyvind Holmstad, CC BY-SA 4.0, via Wikimedia Commons" width="320" /></a></div>At some point last millenium I had control over the heating and air condition for a reasonably sized building. There was a GUI or you could telnet into the machine it was running on. At last resort you could go up to the roof where there was a room full of bit switches that made a really satisfying clunk when you threw them (do people still throw switches or has that gone out of fashion).<div>The system wasn't very sophisticated, it basically knew if a room was supposed to be in use at that time or not and what temperature it was supposed to be if it was (or indeed wasn't).</div><div>There were sensors so it knew what the actual temperature was in each room and it could control valves to let hot water into radiators or cold water into HVAC units. What more could you want?</div><div>Well the thing is that as companies have tried to bring this sort of thing into the home they have given people systems that learn the times they are in the house and allowed control from anywhere in the world. This has often been done by pulling a lot of the control aspect of the products away from a computer that is attached to the the systems directly and into the cloud.</div><div>Which would be fine except that there have been a number of situations where this had lead to the same sort of security flaws as with the Internet of Things or the cloud services being turned off so the hardware in people's houses isn't smart any more.</div><div>You still see the 7-day all-in-one controller and thermostat unit, the only visual difference being that they now tend to be white instead of beige and just of a pain to program, although some of them are now wireless. But they still only tend to control one service. </div><div>In boutique hotels and karaoke suites you get multi service automation, one touch button at the door turns everything on/off and puts it into moods, but these are just flipping relays and you can't say "I'll be back at 6:30, make it 22° and run a bath"</div><div>Who is taking the best bit of all three approaches, smart(ish do we need things to learn our habits, just tell them, or give them an ical feed), all the processing power in the house so it doesn't get bricked by the supplier going bust or being bought out, multi-service "lights, camera, action", and securely controllable from outside the house. Okay two of those may be contradictory, you need some remote reliance to get the message through but if that is all you lose when it breaks, or indeed if you could replace that service because it is documented not proprietary.</div><div>Where should I be looking for the friendly packaged control software in a box, with minimal secure external services, and a decent sized set of interfaces into other systems?</div><div class="blogger-post-footer"><a rel="license" href="http://creativecommons.org/licenses/by-sa/2.0/uk/">
<img alt="Creative Commons License" style="border-width:0" src="http://www.pint.org.uk/stuff/cc.png" />
</a></div>Tonyhttp://www.blogger.com/profile/00446535470734199043noreply@blogger.com18tag:blogger.com,1999:blog-3363708686706070383.post-53278733782253173812020-12-24T11:01:00.001+00:002020-12-24T11:01:26.459+00:00That pulse oximeter scandal<p></p><div class="separator" style="clear: both; text-align: center;"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjWvAdIsj5N0kv4Xz1V85jOTAr7cjAvBw4YcDNylj1RQRA_rhVJH2oj4ygGZfQJPsrapuzNUxW-CpcbPs5U2e5vhfDu34ujxyM5rSv38vDuXAo4VD-t8JPMa7j0C2uPsXE1mzj9Q18vjr7n/s2140/pulseOxandApple.png" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"><img alt="A pulse oximeter on a finger above an apple watch on a wrist." border="0" data-original-height="2140" data-original-width="1054" height="400" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjWvAdIsj5N0kv4Xz1V85jOTAr7cjAvBw4YcDNylj1RQRA_rhVJH2oj4ygGZfQJPsrapuzNUxW-CpcbPs5U2e5vhfDu34ujxyM5rSv38vDuXAo4VD-t8JPMa7j0C2uPsXE1mzj9Q18vjr7n/w198-h400/pulseOxandApple.png" title="Similar?" width="198" /></a></div>Something has been bugging me since I first saw the story that <i><a href="https://www.nytimes.com/2020/12/22/health/oximeters-covid-black-patients.html?fbclid=IwAR3lJuU9xkmGMZOw-Duc51DxaVc9aPd3rEdTh1-sd5RBWNYMO7UCM_4DkTA" target="_blank">Pulse Oximeter Devices Have Higher Error Rate in Black Patients</a></i> other than the <b>very obvious racism</b>.<p></p><p>Say you have decided that the way in which white people decide they are the default and don't bother to do any work to see how the technology they sell affects people with different skin colours is a lesser evil than actively joining the clan.</p><p>Say you also accept that not a single one of the companies that makes pulse oximeters managed to see a copy of <i><a href="https://pubs.asahq.org/anesthesiology/article/102/4/715/7364/Effects-of-Skin-Pigmentation-on-Pulse-Oximeter" target="_blank">Effects of Skin Pigmentation on Pulse Oximeter Accuracy at Low Saturation (April 2005)</a></i> or similar.</p>
<p>In order to forgive oversite in this matter you also have to believe that collectively the companies manufacturing these devices and/or integrating them into more complex products have at no point seen any coverage of the controversy around Apple Watches on dark skin, which to be frank was everywhere five years ago.</p><p>I don't know about you, but as someone working in the technology product space, my first reaction whenever there is a story about a product failing in a similar space to mine is to go and ask the specialists "are we vulnerable to the same problem" because (and shamefully so) in terms of reputation damage, worse than being called out for racism, worse than being in the papers/Private Eye/The Register for your product being broken, is being the company whose product is still broken in a way that everyone noticed five years ago and fixed. After all while learning from your mistakes is very important, learning from other people's mistakes is better.</p><p>So either there are loads of product types in medical technology that are failing people because they don't engage with the wider technology space, or they spotted this and decided to keep their head down to avoid costs, or worst of all pulled on white hoods and decided that non-pale-skinned people weren't worth R&D time.</p><p>As I said at the beginning, there are those that are happy to dismiss accidental racism as acceptable and I'd be lying if I said I was confident I'd never done it myself, but in this case people are actively not doing their job.</p><p>P.S. If I have failed to spot someone more appropriate to make this point posting on it, please get in touch and let me know and I'll promote their writing instead.</p>
<div class="blogger-post-footer"><a rel="license" href="http://creativecommons.org/licenses/by-sa/2.0/uk/">
<img alt="Creative Commons License" style="border-width:0" src="http://www.pint.org.uk/stuff/cc.png" />
</a></div>Tonyhttp://www.blogger.com/profile/00446535470734199043noreply@blogger.com8tag:blogger.com,1999:blog-3363708686706070383.post-25158274945738244182020-11-03T09:32:00.001+00:002020-11-03T09:32:23.574+00:00American Voting<h2>Happy Election day!</h2>
<p>Alongside all the other reasons to be watching the American elections I have been looking at how they implement the actual voting part. In previous years a lot of the coverage in this area has been about voting machines, from hanging chads to hacking. But a number of things this year seem like they are both good ideas in general and implementable in a UK general election.</p><h3>Early Voting</h3>
<p>This is the easiest to endorse, it has even been trialed in the UK (I'll see if I can find the report later). The way the trial worked, a centralised location, marking off voters on the actual paper copies of the electoral roll that would then be issued to polling stations to prevent repeats, fitted in with the british electoral esthetic that in general thinks the most complex piece of technology in use should be a peg.</p>
<h3>Kerbside/drive through Voting</h3>
<p>One of the really big issues with polling stations in the UK is accessibility. So providing an alternate option that improves access to voting has to be a good thing. Given that there would be limited venues available in order to not require pre-registration it would probably need to also be a pre-election day activity. Also if we were going to stick to the idea that there is "one true copy" of the register then there would need to be a system to avoid allowing people to use both forms of early voting. Off the top of my head, the "inner envelope" part of postal voting, so until the voting lists can be cross checked the ballot can be linked to the voter and destroyed if a duplicate.</p>
<h3>Postal Ballot Acknowledgement</h3>
<p>A tonne of the commentary running up to the election has been that the postal service has been used as a political football. As a consequence of this there have been a lot of articles around the subject of "What to do if your postal ballot doesn't arrive or is rejected". I was intrigued that being able to check up on this was a thing. And while this would require the use of technology, it is an enhancement (assuming a general low level of ballots missing/rejected) that if broken wouldn't halt the election so it shouldn't be dismissed out of hand. So a simple website that tells people their ballot has been received, signatures matched etc. would allow people to spot rejections and do something about it.</p><p></p><div class="blogger-post-footer"><a rel="license" href="http://creativecommons.org/licenses/by-sa/2.0/uk/">
<img alt="Creative Commons License" style="border-width:0" src="http://www.pint.org.uk/stuff/cc.png" />
</a></div>Tonyhttp://www.blogger.com/profile/00446535470734199043noreply@blogger.com9tag:blogger.com,1999:blog-3363708686706070383.post-15109631412651614782020-10-29T14:01:00.000+00:002020-10-29T14:01:17.898+00:00Writing with a pencil taped to a brick<blockquote><div class="separator" style="clear: both; text-align: center;"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzKNMU7me9VmGmtZehPiv8E6zao9num20Vav6gMjZ82WPCu_UJGKOBYX4X83a82nwbCaqo4C2I1ERyLUcPbi1ECGWa3Xfn-8IXp3876427Lj-ECf220C5zrAm2J_4dRt4dMoHdH3UihUKp/s668/123141782_10101799109958882_1646162581155799788_n.jpg" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"><img alt="Someone writing with a pencil with a house brick taped to it." border="0" data-original-height="668" data-original-width="590" height="177" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzKNMU7me9VmGmtZehPiv8E6zao9num20Vav6gMjZ82WPCu_UJGKOBYX4X83a82nwbCaqo4C2I1ERyLUcPbi1ECGWa3Xfn-8IXp3876427Lj-ECf220C5zrAm2J_4dRt4dMoHdH3UihUKp/w158-h177/123141782_10101799109958882_1646162581155799788_n.jpg" width="158" /></a></div>"One way of explaining to somebody why it could make a significant difference if you can do things faster, is to provide a counter example. So, I had them write with a brick taped to their pencil , because it's only a matter of happenstance that the scale of our body and our tools and such lets us write as fast as we can. What if it were slow and tedious to write? A person doesn't have to work that way very long before starting to realize that our academic work, our books - a great deal would change in our world if that's how hard it had been to write."<br /><strong><a href="https://web.stanford.edu/class/history34q/readings/Engelbart/Engelbart_AugmentWorkshop.html">The Augmented Knowledge Workshop</a></strong></blockquote>
<p>This quote and photo was posted today by a friend who was talking about <a href="https://en.wikipedia.org/wiki/NLS_(computer_system)" target="_blank">the NLS workstation</a>. It immediately resonated with me as a metaphor for how I feel when writing and I wondered if it worked as generalised metaphor for accessibility in digital tools. We have ensured everyone has access to and can use the pencil, are we trying to measure the relative performance users are getting out of the pencil.</p><p>One of the things that hands the pencil to me<small><sup>[1]</sup></small> is a spell checker. What removes the masonry is it actually being any good. This is surprisingly difficult to find trait, for example it is top of the list of things that keeps me paying to use MS Office over some otherwise excellent free alternatives. For those wondering, the difference is in how good they are are trying to work out what the jumble of letters I have input is supposed to be, excellence is the right word being suggested for all but the most egregious errors. Bad is I have to switch to googling to find the right answer. Terrible (and here I am convinced that the one built into Android has got markedly worse recently) is not getting the obvious one letter mistakes.</p><p>I know that this is hardly radical and in terms of my accessibility and usability expert friends I am not so much preaching to the choir but humming Bach to the organist but I feel it is a good reminder for us generalists. I'll now sit back and wait for someone to find a typo.</p>
<br /><hr align="left" width="25%" />
<small><sup>[1]</sup></small>I am aware that I am in a place of huge privilege here in how low the barrier is to my participation, but I find it easier to write from my personal experience.<div class="blogger-post-footer"><a rel="license" href="http://creativecommons.org/licenses/by-sa/2.0/uk/">
<img alt="Creative Commons License" style="border-width:0" src="http://www.pint.org.uk/stuff/cc.png" />
</a></div>Tonyhttp://www.blogger.com/profile/00446535470734199043noreply@blogger.com6tag:blogger.com,1999:blog-3363708686706070383.post-84690011820783243732020-06-11T13:49:00.000+01:002020-06-11T13:49:40.333+01:00Black Lives Matter<div class="separator" style="clear: both; text-align: center;">
</div>
<h2>
Black Lives Matter.</h2>
Not much this white guy can add. Although it strikes me that some people<sup><small>[1]</small></sup> hear "Black Lives Matter" as "white lives don't".<br />
<br />
I think in their mind they see the pie chart below, if the local police department stop killing black people they obviously have to kill more white people to keep up to quota on shooting civilians.
<br />
<div class="separator" style="clear: both; clear: both; text-align: center; text-align: center;">
<a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjwmhKh0yoyXIpPlkwbZm_C6aNiA4qONKD7T5e6RCuqDV_IGJ25kdxBaNmoxLT6GYHVpnuG3z3kwhSatq2Y-JfoXCKoG805c3Lw-GoLzTJ2PA3m4P2cYwakp0P1ktMaNCq0_CSGKdR8EdCm/s1600/blm+pie.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img alt="Pie chart of deaths at the hands of Washington DC police, starts at the correct 93:7 and ends up 100% white." border="0" data-original-height="1066" data-original-width="1240" height="275" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjwmhKh0yoyXIpPlkwbZm_C6aNiA4qONKD7T5e6RCuqDV_IGJ25kdxBaNmoxLT6GYHVpnuG3z3kwhSatq2Y-JfoXCKoG805c3Lw-GoLzTJ2PA3m4P2cYwakp0P1ktMaNCq0_CSGKdR8EdCm/s320/blm+pie.gif" title="" width="320" /></a></div>
<span style="clear: both; display: block; margin-left: auto; margin-right: auto; text-align: center; width: 320px;">
Deaths at the hands of police in Washington DC by race. Data for frame 1 from <a href="https://github.com/washingtonpost/data-police-shootings">The Washington Post</a></span>
<br />
<br />
They should of course be seeing and therefore wanting<sup><small>[2]</small></sup> this bar chart:
<br />
<div class="separator" style="clear: both; text-align: center;">
<a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi5Eb4MHWUQfCfG9kz9p3uIqnnVvhYDk_ZG3_u0bCyXEuNy1516hRu1YD1mJtTB_JONejDWjjPUb4d_uDJxQ4htQ2qjIpIlrtSPwDoLCHZCgDj5HyeViMZ_LhvllHdh0GXXgKp7A2o6xKLQ/s1600/blm+bar.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img border="0" data-original-height="1066" data-original-width="1240" height="275" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi5Eb4MHWUQfCfG9kz9p3uIqnnVvhYDk_ZG3_u0bCyXEuNy1516hRu1YD1mJtTB_JONejDWjjPUb4d_uDJxQ4htQ2qjIpIlrtSPwDoLCHZCgDj5HyeViMZ_LhvllHdh0GXXgKp7A2o6xKLQ/s320/blm+bar.gif" width="320" /></a></div>
This happens time after time.<br />
False equivalence, inappropriate but near religious worship of the zero sum game, and on occasion just plain ridiculousness.<br />
<blockquote class="tr_bq">
"Take down statues of people who murdered and enslaved people." Response from some people<sup><small>[1]</small></sup> "They take one of ours, we take one of theirs, pull down the statues of Muhammad<sup><small>[3]</small></sup>"</blockquote>
because somehow there needs to be balance in statue removal, or
<br />
<blockquote class="tr_bq">
"Please consider looking at the names of your pubs and beers and remove racist names and iconography" "They'll be banning 'The White Horse' and 'The Red Lion' next"
</blockquote>
I don't want to dilute this post with examples from other situations. But it is amazing how often privileged people think someone else getting treated like a human being, and efforts being made to ensure they get the same rights as everyone else, as a loss of some of their rights.<br />
<hr />
<sup>[1]</sup> Racist white people mainly.<br />
<sup>[2]</sup> Surely everyone wants zero deaths at the hands of police. This is of course means no need for them to have to shoot at people, so no mass shootings<sup><small>[1]</small></sup> <br />
<sup>[3]</sup>I shall leave quite how ridiculous this is as an exercise for the reader.<div class="blogger-post-footer"><a rel="license" href="http://creativecommons.org/licenses/by-sa/2.0/uk/">
<img alt="Creative Commons License" style="border-width:0" src="http://www.pint.org.uk/stuff/cc.png" />
</a></div>Tonyhttp://www.blogger.com/profile/00446535470734199043noreply@blogger.com7tag:blogger.com,1999:blog-3363708686706070383.post-86291023109976243962020-01-24T12:09:00.002+00:002020-01-24T12:09:59.702+00:00Skypemathics<p>The first nonabsolute number is the number of people who will attend the conference call. This will vary during the course of the first three emails, and then bear no apparent relation to the number of people who actually turn up, or to the number of people who subsequently join them after another meeting, or to the number of people who leave when they see who else has turned up.</p>
<p>The second nonabsolute number is the start time of the conference call, which is now known to be one of those most bizarre of mathematical concepts, a recipriversexclusion, a number whose existence can only be defined as being anything other than itself. In other words, the given time of arrival is the one moment of time at which it is impossible that any member of the call will log on. Recipriversexclusions now play a vital part in many branches of maths, including statistics and accountancy and also form the basic equations used to engineer the Somebody Else's Problem field.</p>
<p>The third and most mysterious piece of nonabsoluteness of all lies in the relationship between the number of actions in the minutes, the number of people in the conference call and what they are each prepared to be responsible for. (The number of people who actually have any responsibility is only a subphenomenon in this field.)</p>
<p>Numbers written on emails about conference calls do not follow the same mathematical laws as numbers written on any other communications in any other parts of the universe.</p>
<p>With huge apologies to Douglas Adams.</p><div class="blogger-post-footer"><a rel="license" href="http://creativecommons.org/licenses/by-sa/2.0/uk/">
<img alt="Creative Commons License" style="border-width:0" src="http://www.pint.org.uk/stuff/cc.png" />
</a></div>Tonyhttp://www.blogger.com/profile/00446535470734199043noreply@blogger.com19tag:blogger.com,1999:blog-3363708686706070383.post-55215543898942956272018-01-20T12:26:00.001+00:002018-01-20T12:26:43.465+00:00And another thing<p dir="ltr"><a href="http://blog.pint.org.uk/2018/01/the-trouble-with-trains.html">On the subject of trains</a>…</p>
<p dir="ltr">The other thing that strikes me is how often the railway debate is seen as binary. As-is verses monolithic state owned-and-run.</p>
<p dir="ltr">This isn't just when talking about the future of the British railways but when citing the best and worst bits of the situation in other countries.</p>
<p dir="ltr">No small changes or mixed models allowed. All mentions of "and this happens where they have a nationalised system" talks of separation of running trains and infrastructure or that private companies can still run services or use of private contractors (I know lots of people are chiming sonorous dirges about outsourcing due to Carillion, but I don't think it will, or should, be going away).</p>
<p dir="ltr">What if a government stopped letting franchises for local services at first? Or transformed contracts to be a different sort of private operation like TfL do with the Overground etc? Has anyone done a comprehensive independent analysis of the options showing the pros and cons?</p>
<p dir="ltr">Is the all or nothing a straw man awaiting the flame or somehow the only two options?</p>
<div class="blogger-post-footer"><a rel="license" href="http://creativecommons.org/licenses/by-sa/2.0/uk/">
<img alt="Creative Commons License" style="border-width:0" src="http://www.pint.org.uk/stuff/cc.png" />
</a></div>Tonyhttp://www.blogger.com/profile/00446535470734199043noreply@blogger.com4tag:blogger.com,1999:blog-3363708686706070383.post-37080132742096690682018-01-20T11:52:00.001+00:002018-01-20T22:47:06.884+00:00The trouble with trains<div dir="ltr">
As per usual when the January regulated rail prices were announced there was a lot of comment about and around them.</div>
<div dir="ltr">
A big theme was asking Labour if they still wanted to nationalise the railways and then writing about why this was a bad idea.</div>
<div dir="ltr">
But rather than actually analyzing the concept as a whole, because season tickets and full price returns costs had been the story prompt, lots of the criticism was that cutting these fares mostly subsidized the better off segments of travellers.</div>
<div dir="ltr">
The problem with this is<br />
a) assuming that big cuts to these prices would be the first and only change a nationalising government would make to the charging structure.<br />
b) that nationalisation would be an isolated action (which is I suppose a fair enough way to make understanding the consequences easier)<br />
but biggest of all<br />
c) that this is a nationalisation issue in the first place.<br />
<br /></div>
<div dir="ltr">
<b>These are regulated fares</b>. They are set by rules outside of the train operating companies hands. If an administration of any hue wanted to deal with this issue they could just (yes I know that is a huge just and would probably require a complete cycle of reletting franchises but that isn't that long in governmental terms) change the rules. We could have a whole new pricing structure with very little change to the way the railways work otherwise if there was political will.</div>
<div dir="ltr">
There are many other issues with how railway "ownership" works currently and what model would be best (in general, there would always be losers in any change) for the country but every January this one rankles.</div>
<div class="blogger-post-footer"><a rel="license" href="http://creativecommons.org/licenses/by-sa/2.0/uk/">
<img alt="Creative Commons License" style="border-width:0" src="http://www.pint.org.uk/stuff/cc.png" />
</a></div>Tonyhttp://www.blogger.com/profile/00446535470734199043noreply@blogger.com13tag:blogger.com,1999:blog-3363708686706070383.post-53702245225247050402018-01-20T11:17:00.000+00:002018-01-20T11:17:08.021+00:00Secure messaging for public health<div>
<b>EDIT</b>: That thing where you think you've published a blog post before running out to Thanksgiving dinner, then find it in your drafts.</div>
<div>
<br /></div>
So the other day I spotted this tweet about the adoption of secure messaging in public health pootling past on my timeline (you may want to glance at the blog post linked to in the parent tweet).<br />
<blockquote class="twitter-tweet" data-lang="en">
<div dir="ltr" lang="en">
The issue is that WhatsApp (Facebook) have a desire to monetise what goes through its servers in the US and that should concern us if using confidential information. Platforms like Signal might be the answer, or building in house wouldn’t be that hard.</div>
— Daniel McGuinness (@dannymcg) <a href="https://twitter.com/dannymcg/status/929501189305184258?ref_src=twsrc%5Etfw">November 12, 2017</a></blockquote>
<script async="" charset="utf-8" src="https://platform.twitter.com/widgets.js"></script>
and being me stepped in to suggest yes it probably would be that hard. If not much, much harder<br />
<br />
There was a bit of a debate, some people suggested that NHS IT projects were only ever difficult and expensive because outsourcing companies ripped off the public sector. I'm not going to defend any of those outfits, but their greed isn't the only reason that such projects are costly. Besides "In House" these days could mean actually properly in house as <a href="https://digital.nhs.uk/" target="_blank">the NHS seems to be getting serious about digital.</a><br />
<br />
There were some constructive contributions such as<br />
<blockquote class="twitter-tweet" data-conversation="none" data-lang="en">
<div dir="ltr" lang="en">
No, it is a routine level of difficulty for people who are available.<br />
Start with GNU and Ross Anderson's department.</div>
— Adrian Midgley (@amidgley) <a href="https://twitter.com/amidgley/status/929514172051742720?ref_src=twsrc%5Etfw">November 12, 2017</a></blockquote>
<script async="" charset="utf-8" src="https://platform.twitter.com/widgets.js"></script>
<br />
Looking into what open source software is out there is always a good idea, as is looking at the research behind the algorithms. As an example <a href="https://github.com/whispersystems/libsignal-protocol-c" target="_blank">the protocol behind the Signal messaging app</a> is available <a href="http://www.gnu.org/licenses/gpl-3.0.html" target="_blank">under the GPL</a>. So with appropriate due diligence for ensuring that it is secure, you are using a genuine untampered with version etc it would provide a good starting point. Of course other protocols are available.<br />
<h4>
So isn't it that easy?</h4>
No. For two main reasons. Firstly security. Strangely for all the reasons successive Home Secretaries have been wrong about the "dangers" of end-to-end security the NHS may well consider it a genuine issue. Audit trails, patients rights to personal data, the bus stop problem, safeguarding, and a million other reasons means that <b>private end-to-end encrypted communications between two health professionals could be an issue</b>.<br />
<br />
While the protocol you have chosen may have ways to deal with this, an audit server as a compulsory participant in every conversation for example, you then have a lot of traffic that has to be securely stored. As this is being kept for logging and monitoring any metadata products have to both be referenced by participants and subjects<small><sup>[1]</sup></small> while also being secured to keep anyone from using inference attacks<small><sup>[2]</sup></small>, and so on. <b>Good cryptography is bloomin' hard</b> and the more participants you involve the harder it gets.<br />
<h4>
And secondly?</h4>
If you didn't know before then <a href="https://www.theguardian.com/technology/2017/may/13/cyber-attack-on-nhs-sparks-bitter-election-battle">the rapid spread of WannaCry through parts of the NHS technical estate</a> highlighted quite how fragmented and antiquated that estate is. In fact I would go so far as to say that for the purposes of discussing a project like this <b>there is no "The NHS" </b>even if we, for the purposes of discussion, stick to England the enormity of the number of organisational units is frankly overwhelming. Who needs to be included? Trusts,CCGs, special health authorities, GPs, pharmacists, optometrists, dentists, private sector service suppliers, local authorities, universities? While you can accurately accuse me of hyperbole in having the list that long it doesn't matter.<br />
<br />
Even if you just wanted to have this service for Acute Trusts the number and type of devices that would need to be supported is going to be the source of most of the development, testing and roll-out costs. Unlike an informational website where you can make a choice to have it look less polished in older browsers so long as it gets the point across, nobody will sign off "this will be less secure on X, Y, and Z". Although to be fair it is far more likely "It just won't work on X, Y, and Z" as they won't support the features required.<br />
<div>
<br /></div>
<div>
Even if you could put together a dedicated team, formed of literally the best people for the job and magicaly ensure they were uninterrupted and as efficient as humanly possible. Even if not a single minute or pound was wasted. The design phase would take longer than most onlookers would set asside to have the whole thing live.<br />
<br />
Hopefully I'll find some time soon to do a post about the other side of the coin, all the exciting things that could be done with a good, well provisioned, secure messaging platform for public health.<br />
Please do challenge my assumptions and/or conclusions in the comments <a href="https://twitter.com/thegreatgonzo" target="_blank">or on twitter.</a>
<br />
<hr />
<sup>[1]</sup>This sort of thing is going to become increasingly important as we all get more rights to our personal data<br />
<sup>[2]</sup>There is no point in using high security methods to protect the text of the conversation about cancer treatment protocols to protect someone's privacy if you use lower standards on the information "oncologist X and oncologist Y talked about patient N"</div>
<div class="blogger-post-footer"><a rel="license" href="http://creativecommons.org/licenses/by-sa/2.0/uk/">
<img alt="Creative Commons License" style="border-width:0" src="http://www.pint.org.uk/stuff/cc.png" />
</a></div>Tonyhttp://www.blogger.com/profile/00446535470734199043noreply@blogger.com7tag:blogger.com,1999:blog-3363708686706070383.post-50518566809959875612017-03-15T16:57:00.000+00:002017-03-15T18:31:33.165+00:00Is equal "Equality"<div dir="ltr">
On the face of it the face of it you might think that the European Court of Justice ruling "<a href="http://www.independent.co.uk/news/world/europe/european-court-justice-islamic-headscarf-hijab-ban-employers-legal-religious-symbols-case-belgium-a7628626.html">An internal rule of an undertaking which prohibits the visible wearing of any political, philosophical or religious sign does not constitute direct discrimination</a>" was fair and equal. As long as applies to it applies to everything right?</div>
<div dir="ltr">
<br /></div>
<div dir="ltr">
Well no.</div>
<div dir="ltr">
<br /></div>
<div dir="ltr">
Firstly even if you don't believe in a religion[1] then I'm sure you can understand the concepts behind them. There are people who sincerely think that the consequences in the long term (damnation) are worse than now (starvation).</div>
<div dir="ltr">
<br /></div>
<div dir="ltr">
So you can't be convinced by that, next is there are some that even if they decide they think employment is more important than religion can't do anything about it. Culturally they'll be stopped by family, spouses, elders or other leaders. This will be by some form of real or threatened violence. It may not be what we want for people, but it is reality and realistically unfixable.</div>
<div dir="ltr">
<br /></div>
<div dir="ltr">
Next if you look at the context of this against other rules and laws in Europe that have come out over the last few years, this is obviously part of rising islamophobia. It may as much about turbans, yarmulkes, crosses, political party insignia and cameos of epistemologists but look at the coverage everyone knows what it is really about.</div>
<div dir="ltr">
<br /></div>
<div dir="ltr">
Even worse:</div>
<blockquote class="tr_bq">
“However, in the absence of such a rule, the willingness of an employer to take account of the wishes of a customer no longer to have the employer's services provided by a worker wearing an Islamic headscarf cannot be considered an occupational requirement that could rule out discrimination.”</blockquote>
<div dir="ltr">
means that when a company starts pandering to racists it has to screw over the whole workforce.</div>
<div dir="ltr">
<br /></div>
<div dir="ltr">
EDIT: <a href="http://parliamentlive.tv/event/index/9bbf17eb-702e-4495-8bd7-cf038238d8ac?in=13:23:48">HMG have clarified their opinion on how this effects UK companies</a>.</div>
<div dir="ltr">
<br /></div>
<div dir="ltr">
[1] Doesn't really matter which. If your religion says that bad things will happen, eternal damnation for example, if you don't follow the rules, you should be able to understand someone else's does also. If you can't muster up such basic empathy begone with you.</div>
<div class="blogger-post-footer"><a rel="license" href="http://creativecommons.org/licenses/by-sa/2.0/uk/">
<img alt="Creative Commons License" style="border-width:0" src="http://www.pint.org.uk/stuff/cc.png" />
</a></div>Tonyhttp://www.blogger.com/profile/00446535470734199043noreply@blogger.com10